57.538 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.538 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-5284 | HIGH 7.5 | google chrome Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-5277 | HIGH 7.5 | google chrome Integer overflow in ANGLE in Google Chrome on Windows prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) | 0.3% | — |
| CVE-2026-50750 | HIGH 7.5 | apache activemq Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Following the fix for CVE-2026-49270 an unauthenticated attacker can now cause broker OOM by sending an repeated BrokerInfo commands without se | 0.7% | — |
| CVE-2026-50734 | HIGH 7.5 | apache activemq Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All. An unauthenticated network attacker can cause a broker DoS by sending a crafted WireFormatInfo frame with a malicious large size value. | 0.7% | — |
| CVE-2026-50696 | HIGH 7.5 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-50695 | HIGH 7.5 | microsoft windows_10_1607 Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-50685 | HIGH 7.5 | microsoft windows_10_1607 Double free in Windows DHCP Server allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-50653 | HIGH 7.5 | microsoft .net_framework Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-50652 | HIGH 7.5 | microsoft .net_framework Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network. | 1.7% | — |
| CVE-2026-50651 | HIGH 7.5 | microsoft .net Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | 0.8% | — |
| CVE-2026-50648 | HIGH 7.5 | microsoft .net Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network. | 0.8% | — |
| CVE-2026-50647 | HIGH 7.5 | microsoft .net_framework Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-50645 | HIGH 7.5 | apache cxf There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF, which can lead to uncontrolled resource consumption or a denial of service attack. Users are recommended to upgrade to versions 4.2.2 | 0.5% | — |
| CVE-2026-50527 | HIGH 7.5 | microsoft .net Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network. | 0.8% | — |
| CVE-2026-50525 | HIGH 7.5 | microsoft .net Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | 0.6% | — |
| CVE-2026-50524 | HIGH 7.5 | microsoft .net Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network. | 0.6% | — |
| CVE-2026-50506 | HIGH 7.5 | microsoft asp.net_core_odata Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-50505 | HIGH 7.5 | microsoft windows_10_1607 Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-50500 | HIGH 7.5 | microsoft windows_10_1607 Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-50496 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network. | 1.2% | — |
| CVE-2026-50470 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-50463 | HIGH 7.5 | microsoft windows_10_1809 Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-50424 | HIGH 7.5 | microsoft windows_11_24h2 Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-50414 | HIGH 7.5 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-50411 | HIGH 7.5 | microsoft .net_framework Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. | 1.2% | — |